8.1.7.2 Ensure That Microsoft Defender for Open-Source Relational Databases Is Set To 'On' (Automated)
Description
Turning on Microsoft Defender for Open-source relational databases enables threat detection for Open-source relational databases, providing threat intelligence, anomaly detection, and behavior analytics in the Microsoft Defender for Cloud.
Rationale
Enabling Microsoft Defender for Open-source relational databases allows for greater defense-in-depth, with threat detection provided by the Microsoft Security Response Center (MSRC).
Impact
Turning on Microsoft Defender for Open-source relational databases incurs an additional cost per resource.
Audit Procedure
From Azure Portal:
- Go to
Microsoft Defender for Cloud. - Under
Management, selectEnvironment Settings. - Click on the subscription name.
- Select the
Defender plansblade. - Click
Select types >in the row forDatabases. - Ensure the toggle switch next to
Open-source relational databasesis set toOn.
From Azure CLI:
az security pricing show -n OpenSourceRelationalDatabases --query pricingTier
From PowerShell:
Get-AzSecurityPricing | Where-Object {$_.Name -eq 'OpenSourceRelationalDatabases'} | Select-Object Name, PricingTier
Ensure output for Name PricingTier is OpenSourceRelationalDatabases Standard.
From Azure Policy:
- Policy ID:
0a9fbe0d-c5c4-4da8-87d8-f4fd77338835- Name: 'Azure Defender for open-source relational databases should be enabled'
Expected Result
The pricing tier for OpenSourceRelationalDatabases should be Standard.
Remediation
From Azure Portal:
- Go to
Microsoft Defender for Cloud. - Under
Management, selectEnvironment Settings. - Click on the subscription name.
- Select the
Defender plansblade. - Click
Select types >in the row forDatabases. - Set the toggle switch next to
Open-source relational databasestoOn. - Select
Continue. - Select
Save.
From Azure CLI:
az security pricing create -n 'OpenSourceRelationalDatabases' --tier 'standard'
From PowerShell:
set-azsecuritypricing -name "OpenSourceRelationalDatabases" -pricingtier "Standard"
Default Value
By default, Microsoft Defender plan is off.
References
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-overview
- https://learn.microsoft.com/en-us/rest/api/defenderforcloud/pricings/update
- https://learn.microsoft.com/en-us/powershell/module/az.security/get-azsecuritypricing
Profile
- Level 2